210K MultiCare Health System and Woodcreek Healthcare Patients Affected by Ransomware Attack

By | March 10, 2021

The number of individuals affected by a ransomware attack on St. Cloud-based Netgain Technology LLC has increased, with a further 210,000 individuals now known to have been affected. Netgain Technology provides IT and technology services to several entities in the healthcare industry, including the medical practice management company Woodcreek Provider Service in Washington. Ramsey County in Minnesota was previously confirmed to have been affected by the ransomware attack.

Woodcreek Provider Service provides support to pediatric clinics and urgent care centers owned and operated by MultiCare Health System.  Woodcreek Provider Service was notified by Netgain about the December 3, 2020 attack and informed that the protected health information of patients and the personal information of employees and contractors were stored on servers affected by the ransomware attack, and may have been obtained by the attackers who first gained access to its systems on November 23, 2020.

The Woodcreek Provider Service IT network and computer system is hosted by Netgain and a considerable amount of data has potentially been accessed or obtained in the extortion attack. Potentially compromised information includes: Names, addresses, medical record numbers, dates of birth, Social Security numbers, health insurance information, insurance claims, explanation of benefits statements, clinical notes, referral requests, lab test reports, decision not to vaccinate forms, authorization requests for services, treatment approvals, records requests, immunization information, vaccine records, prescription requests, release of information forms, subpoena records requests, medical record disclosure logs, incident reports, invoices, correspondence with patients, student identification numbers, bank account numbers, employment related documents, court documents, DEA certificates, payroll withholding and insurance deduction authorizations, benefit and tax forms, employee health information and some medical records.

The data stolen in the attack was returned when the ransom was paid and assurances were received that no data was retained by the attackers. Netgain provided reassurances that steps have been taken to improve security to prevent any further cyberattacks. Woodcreek Provider Service has also taken steps to protect information under its control and has reviewed and revised its cybersecurity policies and procedures.

Affected MultiCare Health System and Woodcreek Healthcare patients have been offered identity theft protection services and/or complimentary credit monitoring services.

Sandhills Medical Foundation has Data Stolen in Ransomware Attack

Sandhills Medical Foundation has also started notifying patients that some of their protected health information was obtained in a ransomware attack on a vendor that provides data storage for its billing, scheduling, and reporting systems. While it has not been confirmed which vendor suffered the attack, the timings provided in the breach notice and nature of the referenced vendor make it likely that it was Netgain Technologies.

Sandhills Medical Foundation was notified by the vendor on January 8, 2021 and was informed that the attackers accessed Sandhills’ systems on November 15, 2020 and stole data. The ransomware was deployed on December 3, 2020. The data obtained by the attackers included names, dates of birth, email addresses, mailing addresses, driver’s license numbers, Social Security numbers, and claims information, from which it would be possible to determine diagnoses.  All copies of the stolen data have reportedly been deleted/destroyed.

Affected individuals have been offered complimentary credit monitoring services for 12 months. Sandhills reported the breach to the HHS’ Office for Civil Rights, but the incident has yet to appear on the breach portal so it is currently unclear how many patients have been affected.

The post 210K MultiCare Health System and Woodcreek Healthcare Patients Affected by Ransomware Attack appeared first on HIPAA Journal.